Craftcms
Craftcms Craft CMS: vulnerabilities and CVEs
Craftcms Craft CMS has 160 published vulnerabilities, 103 of them in the last 12 months. 13 are rated critical and 4 are listed by CISA as actively exploited.
CVEs160
Last 12 months103
Critical13
Actively exploited4
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32432 | Critical (10) | 100% | ⚠ Active exploitation | Apr 25, 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft… |
| CVE-2025-35939 | Medium (6.9) | 1.3% | ⚠ Active exploitation | May 7, 2025 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require… |
| CVE-2024-56145 | Critical (9.3) | 97% | ⚠ Active exploitation | Dec 18, 2024 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv`… |
| CVE-2025-23209 | High (8.1) | 22% | ⚠ Active exploitation | Jan 18, 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73858 | Medium (5.3) | 0.43% | — | Sep 23, 2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered… |
| CVE-2026-92593 | High (8.7) | 0.55% | — | Sep 16, 2026 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a… |
| CVE-2026-92592 | High (8.7) | 0.65% | — | Sep 16, 2026 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC… |
| CVE-2026-92591 | High (8.2) | 0.41% | — | Sep 16, 2026 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed… |
| CVE-2026-92590 | Medium (5.1) | 0.24% | — | Sep 16, 2026 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can… |
| CVE-2026-92589 | Medium (5.3) | 0.26% | — | Sep 16, 2026 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but… |
| CVE-2026-79987 | High (8.7) | 0.65% | — | Sep 10, 2026 | A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker. |
| CVE-2026-86732 | High (8.7) | 0.85% | — | Sep 8, 2026 | Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter.… |
| CVE-2026-86731 | High (7.1) | 0.31% | — | Sep 8, 2026 | Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does… |
| CVE-2026-86730 | High (8.7) | 0.71% | — | Sep 8, 2026 | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post… |
| CVE-2026-79991 | High (7.1) | 0.51% | — | Sep 2, 2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering… |
| CVE-2026-79990 | High (8.7) | 0.45% | — | Sep 2, 2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering… |
| CVE-2026-84802 | Medium (5.3) | 0.28% | — | Sep 2, 2026 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit… |
| CVE-2026-84801 | High (8.7) | 0.44% | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator… |
| CVE-2026-84800 | High (7.1) | 0.35% | — | Sep 2, 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target… |
| CVE-2026-84799 | Medium (5.3) | 0.28% | — | Sep 2, 2026 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can… |
| CVE-2026-84798 | High (7.1) | 0.35% | — | Sep 2, 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs… |
| CVE-2026-84797 | Medium (5.3) | 0.29% | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts.… |
| CVE-2026-84796 | High (8.7) | 0.47% | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to… |
| CVE-2026-84795 | Critical (9.2) | 0.51% | — | Sep 2, 2026 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit… |
| CVE-2026-84794 | High (7.1) | 0.35% | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users'… |
| CVE-2026-84793 | Medium (4.8) | 0.25% | — | Sep 2, 2026 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the… |
| CVE-2026-84792 | Medium (5.3) | 0.29% | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers… |
| CVE-2026-79988 | High (8.7) | 0.45% | — | Aug 27, 2026 | The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. |
| CVE-2026-78416 | High (8.7) | 1.0% | — | Aug 24, 2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in… |
| CVE-2026-52889 | Critical (9.8) | 1.3% | — | Aug 19, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query… |
| CVE-2026-72787 | Medium (5.1) | 0.26% | — | Aug 12, 2026 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can… |
| CVE-2026-72786 | High (7.1) | 0.46% | — | Aug 12, 2026 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission… |
| CVE-2026-72785 | Critical (9.3) | 0.27% | — | Aug 11, 2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify… |
| CVE-2026-72784 | Medium (6.9) | 0.24% | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.